The router is the one device every bit of your home's internet traffic passes through. It is also the device least often touched. Installed by a technician at sign-up, then left to work until something goes wrong.

Most of the default settings are adequate. But a few are left loose for the sake of easy installation, and those are the ones to check. Once, and then never think about again.

Getting into the admin page

Type 192.168.1.1 or 192.168.0.1 into a browser. Some brands use other addresses: TP-Link often at tplinkwifi.net, Asus at router.asus.com. The address and default credentials are usually on a sticker underneath the device.

If the sticker is gone and the password is unknown, holding the reset button for 10 seconds restores factory settings. The consequence is that all configuration is lost, including the ISP connection details. Make sure you have a record before pressing it.

1. Change the admin password, not just the Wi-Fi password

These two are different and frequently confused. The Wi-Fi password is used to join the network. The admin password opens the router's settings page.

Many routers leave the factory with admin/admin or admin/password. Anyone already connected to your Wi-Fi, including a guest you gave the password to, can open that page and change anything.

2. Use WPA2 or WPA3, not WEP

WEP can be broken in minutes and should no longer appear on new equipment. If your router still offers it, that is a sign its age is worth considering.

ModeStatusNotes
WEPDo not useBreakable with free tools
WPAAvoidObsolete, only for very old devices
WPA2-PSK (AES)SecureThe most compatible choice today
WPA2/WPA3 mixedRecommendedOlder devices can still join
WPA3BestSome older devices do not support it

If there is a "WPA2 + WPA3" option, take it. New devices use WPA3, older ones still connect over WPA2.

3. Turn off WPS

WPS lets devices join by pressing a button or entering an eight-digit PIN. The PIN part is the problem: its design allows the PIN to be guessed within hours, because it is verified in two separate halves.

The physical button is relatively safe, since it is only active for a few minutes and requires physical access to the router. But many routers enable both at once. If you rarely add new devices, switching WPS off entirely will not feel like an inconvenience.

4. Turn off remote management

The name varies: "Remote Management", "WAN Access", "Web Access from WAN", or "Cloud Access". They all mean the same thing, exposing the admin page so it can be reached from outside the house.

The feature is useful if you manage a family member's router remotely. If not, it merely adds a door. Home routers are among the most frequently attacked devices automatically, because there are so many of them and their firmware is rarely updated.

Watch UPnP too. This feature lets applications open ports on the router without asking you. Useful for games consoles and some applications, but also exploitable by malware. Switch it off if nothing breaks afterwards.

5. Update the firmware

Check the "Firmware Upgrade" or "System Update" menu. Some newer routers update themselves; older ones need a manual download from the manufacturer's site.

This is the step most often skipped and the one with the greatest effect. A security hole found in one model generally applies to hundreds of thousands of identical units. A firmware update is the only way to close it.

If the manufacturer has stopped releasing updates for your model, that is a serious reason to replace it. See the guide to choosing a router before buying.

6. Create a guest network

Almost every modern router has a guest network feature. It has its own name and password, and generally cannot see devices on the main network.

It is not only for guests. Smart devices, cameras, lights, Wi-Fi plugs, belong here too. Such devices often run make-do firmware and are rarely updated, so they are better kept away from your laptop and your NAS.

The same principle applies to guest networks at a business, at a different scale. That is discussed in the guide to Wi-Fi for business.

7. Check the connected device list

The "Attached Devices", "Client List", or "DHCP Clients" menu shows everything currently connected. Open it occasionally and match it against what you recognise.

It has to be admitted the list is often confusing. Device names sometimes appear as strings of digits, and one phone can appear twice if it alternates between 2.4 GHz and 5 GHz. The most reliable method is to switch Wi-Fi off on every device you know, then see what remains.

8. Change the DNS if useful

Routers use the ISP's DNS servers by default. Switching to another provider sometimes speeds up page loading and adds filtering of dangerous sites. Cloudflare (1.1.1.1) and Google (8.8.8.8) are two commonly used.

What needs understanding: changing DNS does not hide your activity from your ISP. It only moves who answers the question "what is this site's IP address". To hide where a connection is going, what you need is a VPN.

9. Record the configuration

Once finished, save a configuration backup through the "Backup Settings" menu. Keep a note too with the admin page address, the admin password, and the network name.

This sounds trivial until the router needs resetting at eleven at night and nobody remembers the PPPoE password from the ISP.

What you do not need to do

Some widely circulated advice adds no meaningful security:

  • Hiding the SSID. The network name is still visible to ordinary scanning tools, and your devices will instead broadcast that name everywhere while looking for it.
  • MAC address filtering. MAC addresses are easily spoofed and plainly visible over the air. All you gain is hassle every time a new device arrives.
  • Reducing transmit power. Useful for reducing overlap between networks, not for security.

None of the three is harmful. It is simply that the effort spent does not match the result, and they often leave people feeling secure while the password is still 12345678.

Kesimpulan

Of the nine above, the three with the greatest effect are the admin password, firmware updates, and turning off remote management. The rest are supporting measures. If time is short, do those three first.

The whole process usually takes twenty minutes. After that the router can go back to being forgotten until the next firmware release.

Frequently asked questions

Does changing the Wi-Fi name (SSID) make the network more secure?

Not directly. Nor does hiding the SSID. Devices still broadcast the name of the network they are looking for, so a hidden network can actually be easier to track. What genuinely matters is a long password and WPA2 or WPA3 encryption.

How often should the Wi-Fi password be changed?

There is no fixed schedule. Change it when someone you no longer want to have access has it, after building work, say, or a change of household help. Changing it monthly for no reason simply pushes people towards shorter passwords.

Should remote management be switched off?

Yes, unless you genuinely use it. The feature exposes the router's admin interface to the internet. If the password is weak or the firmware has a hole, the router can be taken over from anywhere, with no need to be near your house.